<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>69681</bug_id>
          
          <creation_ts>2011-10-07 17:39:42 -0700</creation_ts>
          <short_desc>Fix crash with toDataURL to JPEG</short_desc>
          <delta_ts>2011-10-12 21:56:53 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Canvas</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>69991</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="John Bauman">jbauman</reporter>
          <assigned_to name="John Bauman">jbauman</assigned_to>
          <cc>darin</cc>
    
    <cc>inferno</cc>
    
    <cc>kbr</cc>
    
    <cc>mdelaney7</cc>
    
    <cc>noel.gordon</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>480415</commentid>
    <comment_count>0</comment_count>
    <who name="John Bauman">jbauman</who>
    <bug_when>2011-10-07 17:39:42 -0700</bug_when>
    <thetext>Fix crash with toDataURL to JPEG</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>480416</commentid>
    <comment_count>1</comment_count>
      <attachid>110236</attachid>
    <who name="John Bauman">jbauman</who>
    <bug_when>2011-10-07 17:41:26 -0700</bug_when>
    <thetext>Created attachment 110236
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>480418</commentid>
    <comment_count>2</comment_count>
      <attachid>110236</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2011-10-07 17:44:01 -0700</bug_when>
    <thetext>Comment on attachment 110236
Patch

Can we make a test case to cover this?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>480431</commentid>
    <comment_count>3</comment_count>
      <attachid>110236</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-07 18:48:31 -0700</bug_when>
    <thetext>Comment on attachment 110236
Patch

Rejecting attachment 110236 from commit-queue.

Failed to run &quot;[&apos;/mnt/git/webkit-commit-queue/Tools/Scripts/webkit-patch&apos;, &apos;--status-host=queues.webkit.org&apos;, &apos;-...&quot; exit_code: 2

Last 500 characters of output:
381db9f538a72509ddceba74bc8fa72d7ba8a196
r96996 = 597be029117bbf6b1591194e17018dff0ce3fbd4
Done rebuilding .git/svn/refs/remotes/origin/master/.rev_map.268f45cc-cd09-0410-ab3c-d52691b4dbfc
First, rewinding head to replay your work on top of it...
Fast-forwarded master to refs/remotes/origin/master.
Updating chromium port dependencies using gclient...

________ running &apos;/usr/bin/python gyp_webkit&apos; in &apos;/mnt/git/webkit-commit-queue/Source/WebKit/chromium&apos;
Updating webkit projects from gyp files...

Full output: http://queues.webkit.org/results/9995417</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>481301</commentid>
    <comment_count>4</comment_count>
      <attachid>110439</attachid>
    <who name="John Bauman">jbauman</who>
    <bug_when>2011-10-10 17:01:50 -0700</bug_when>
    <thetext>Created attachment 110439
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>481304</commentid>
    <comment_count>5</comment_count>
      <attachid>110439</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-10 17:05:05 -0700</bug_when>
    <thetext>Comment on attachment 110439
Patch

Rejecting attachment 110439 from commit-queue.

jbauman@chromium.org does not have committer permissions according to http://trac.webkit.org/browser/trunk/Tools/Scripts/webkitpy/common/config/committers.py.

- If you do not have committer rights please read http://webkit.org/coding/contributing.html for instructions on how to use bugzilla flags.

- If you have committer rights please correct the error in Tools/Scripts/webkitpy/common/config/committers.py by adding yourself to the file (no review needed).  The commit-queue restarts itself every 2 hours.  After restart the commit-queue will correctly respect your committer rights.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>481358</commentid>
    <comment_count>6</comment_count>
      <attachid>110439</attachid>
    <who name="Kenneth Russell">kbr</who>
    <bug_when>2011-10-10 17:54:01 -0700</bug_when>
    <thetext>Comment on attachment 110439
Patch

Looks good. r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>481504</commentid>
    <comment_count>7</comment_count>
      <attachid>110439</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-11 01:27:06 -0700</bug_when>
    <thetext>Comment on attachment 110439
Patch

Clearing flags on attachment: 110439

Committed r97132: &lt;http://trac.webkit.org/changeset/97132&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>481505</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-11 01:27:10 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482220</commentid>
    <comment_count>9</comment_count>
    <who name="Abhishek Arya">inferno</who>
    <bug_when>2011-10-11 22:27:11 -0700</bug_when>
    <thetext>This looks like a use after free bug. Can you please confirm soon so that we can merge to m15 ? Do you have a crash id or crash stack ??</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482381</commentid>
    <comment_count>10</comment_count>
    <who name="John Bauman">jbauman</who>
    <bug_when>2011-10-12 06:35:11 -0700</bug_when>
    <thetext>This is a use after free, but it&apos;s not in M15 - it was introduced in r96000.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482975</commentid>
    <comment_count>11</comment_count>
    <who name="noel gordon">noel.gordon</who>
    <bug_when>2011-10-12 19:55:41 -0700</bug_when>
    <thetext>(In reply to comment #2)
&gt; Can we make a test case to cover this?

I reproduced with http://persistent.info/chromium/test-cases/canvas-crash.html, filed bug 69991 about creating a test case.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>110236</attachid>
            <date>2011-10-07 17:41:26 -0700</date>
            <delta_ts>2011-10-10 17:01:46 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-69681-20111007174125.patch</filename>
            <type>text/plain</type>
            <size>1815</size>
            <attacher name="John Bauman">jbauman</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogOTY4NTMKZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwppbmRleCA1MTA1NWJhMjE5N2IzMDBi
NGI0N2M5YmUxNWI0MDc5OTBlNTgzODkxLi4yZWNkYmFiYzVjNTYxZDNkZThjZGE0YzZmYzY5Nzhm
ZmYwYjRlZGI5IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKKysrIGIvU291
cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTggQEAKKzIwMTEtMTAtMDcgIEpvaG4g
QmF1bWFuICA8amJhdW1hbkBjaHJvbWl1bS5vcmc+CisKKyAgICAgICAgRml4IGNyYXNoIHdpdGgg
dG9EYXRhVVJMIHRvIEpQRUcKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19i
dWcuY2dpP2lkPTY5NjgxCisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisK
KyAgICAgICAgTW92ZSBSZWZQdHIgZGVjbGFyYXRpb24gb3V0c2lkZSBpZiB0byBtYWtlIHN1cmUg
aW1hZ2UgZGF0YSBzdGlsbAorICAgICAgICBleGlzdHMgdGhyb3VnaCBDR0ltYWdlVG9EYXRhVVJM
LgorCisgICAgICAgIE5vIG5ldyB0ZXN0cy4gKE9PUFMhKQorCisgICAgICAgICogcGxhdGZvcm0v
Z3JhcGhpY3MvY2cvSW1hZ2VCdWZmZXJDRy5jcHA6CisgICAgICAgIChXZWJDb3JlOjpJbWFnZUJ1
ZmZlcjo6dG9EYXRhVVJMKToKKwogMjAxMS0xMC0wNiAgR2F2aW4gUGV0ZXJzICA8Z2F2aW5wQGNo
cm9taXVtLm9yZz4KIAogICAgICAgICBjb25kaXRpb25hbGl6ZSBtX2NhY2hlZFNjcmlwdCBzdGFj
a3MgdG8ganVzdCBDaHJvbWl1bSBwb3J0CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9wbGF0
Zm9ybS9ncmFwaGljcy9jZy9JbWFnZUJ1ZmZlckNHLmNwcCBiL1NvdXJjZS9XZWJDb3JlL3BsYXRm
b3JtL2dyYXBoaWNzL2NnL0ltYWdlQnVmZmVyQ0cuY3BwCmluZGV4IDcwYWY0ODMxMTc2M2E4OTJm
ZDhmNTQyNDgzMTM0MjE3M2YwY2IwYjEuLmE1OThmYzg3YjcwMjc3M2ZkNzllNWEzMzU4NWZlOWY5
MzI5ZTEwYTcgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2Nn
L0ltYWdlQnVmZmVyQ0cuY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNz
L2NnL0ltYWdlQnVmZmVyQ0cuY3BwCkBAIC0zNjEsMTAgKzM2MSwxMSBAQCBTdHJpbmcgSW1hZ2VC
dWZmZXI6OnRvRGF0YVVSTChjb25zdCBTdHJpbmcmIG1pbWVUeXBlLCBjb25zdCBkb3VibGUqIHF1
YWxpdHkpIGNvbgogICAgIFJldGFpblB0cjxDR0ltYWdlUmVmPiBpbWFnZTsKICAgICBSZXRhaW5Q
dHI8Q0ZTdHJpbmdSZWY+IHV0aSA9IHV0aUZyb21NSU1FVHlwZShtaW1lVHlwZSk7CiAgICAgQVNT
RVJUKHV0aSk7CisgICAgUmVmUHRyPEJ5dGVBcnJheT4gYXJyOwogCiAgICAgaWYgKENGRXF1YWwo
dXRpLmdldCgpLCBqcGVnVVRJKCkpKSB7CiAgICAgICAgIC8vIEpQRUdzIGRvbid0IGhhdmUgYW4g
YWxwaGEgY2hhbm5lbCwgc28gd2UgaGF2ZSB0byBtYW51YWxseSBjb21wb3NpdGUgb24gdG9wIG9m
IGJsYWNrLgotICAgICAgICBSZWZQdHI8Qnl0ZUFycmF5PiBhcnIgPSBnZXRQcmVtdWx0aXBsaWVk
SW1hZ2VEYXRhKEludFJlY3QoSW50UG9pbnQoMCwgMCksIG1fc2l6ZSkpOworICAgICAgICBhcnIg
PSBnZXRQcmVtdWx0aXBsaWVkSW1hZ2VEYXRhKEludFJlY3QoSW50UG9pbnQoMCwgMCksIG1fc2l6
ZSkpOwogCiAgICAgICAgIHVuc2lnbmVkIGNoYXIgKmRhdGEgPSBhcnItPmRhdGEoKTsKICAgICAg
ICAgZm9yIChpbnQgaSA9IDA7IGkgPCB3aWR0aCgpICogaGVpZ2h0KCk7IGkrKykK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>110439</attachid>
            <date>2011-10-10 17:01:50 -0700</date>
            <delta_ts>2011-10-11 01:27:06 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-69681-20111010170154.patch</filename>
            <type>text/plain</type>
            <size>1785</size>
            <attacher name="John Bauman">jbauman</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogOTcxMDQKZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwppbmRleCAxNWM2NzgxMDI3YjBlMDVl
MmYyYWNmZGE0YWM4YTQyOTcyOWU3MDM3Li44YTk5ZmMxZWEyNDRhYTY3NmQ5MDg3ZTlkNzNlZDZk
NDBlZTFjYzgyIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKKysrIGIvU291
cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYgQEAKKzIwMTEtMTAtMTAgIEpvaG4g
QmF1bWFuICA8amJhdW1hbkBjaHJvbWl1bS5vcmc+CisKKyAgICAgICAgRml4IGNyYXNoIHdpdGgg
dG9EYXRhVVJMIHRvIEpQRUcKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19i
dWcuY2dpP2lkPTY5NjgxCisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisK
KyAgICAgICAgTW92ZSBSZWZQdHIgZGVjbGFyYXRpb24gb3V0c2lkZSBpZiB0byBtYWtlIHN1cmUg
aW1hZ2UgZGF0YSBzdGlsbAorICAgICAgICBleGlzdHMgdGhyb3VnaCBDR0ltYWdlVG9EYXRhVVJM
LgorCisgICAgICAgICogcGxhdGZvcm0vZ3JhcGhpY3MvY2cvSW1hZ2VCdWZmZXJDRy5jcHA6Cisg
ICAgICAgIChXZWJDb3JlOjpJbWFnZUJ1ZmZlcjo6dG9EYXRhVVJMKToKKwogMjAxMS0xMC0xMCAg
TmljbyBXZWJlciAgPHRoYWtpc0BjaHJvbWl1bS5vcmc+CiAKICAgICAgICAgUGx1Z2luRG9jdW1l
bnRQYXJzZXIgdXNlcyBpbmNvcnJlY3Qgc3ludGF4IGZvciBiYWNrZ3JvdW5kIGNvbG9yCmRpZmYg
LS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jZy9JbWFnZUJ1ZmZlckNH
LmNwcCBiL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2NnL0ltYWdlQnVmZmVyQ0cu
Y3BwCmluZGV4IDcwYWY0ODMxMTc2M2E4OTJmZDhmNTQyNDgzMTM0MjE3M2YwY2IwYjEuLmE1OThm
Yzg3YjcwMjc3M2ZkNzllNWEzMzU4NWZlOWY5MzI5ZTEwYTcgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9X
ZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2NnL0ltYWdlQnVmZmVyQ0cuY3BwCisrKyBiL1NvdXJj
ZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2NnL0ltYWdlQnVmZmVyQ0cuY3BwCkBAIC0zNjEs
MTAgKzM2MSwxMSBAQCBTdHJpbmcgSW1hZ2VCdWZmZXI6OnRvRGF0YVVSTChjb25zdCBTdHJpbmcm
IG1pbWVUeXBlLCBjb25zdCBkb3VibGUqIHF1YWxpdHkpIGNvbgogICAgIFJldGFpblB0cjxDR0lt
YWdlUmVmPiBpbWFnZTsKICAgICBSZXRhaW5QdHI8Q0ZTdHJpbmdSZWY+IHV0aSA9IHV0aUZyb21N
SU1FVHlwZShtaW1lVHlwZSk7CiAgICAgQVNTRVJUKHV0aSk7CisgICAgUmVmUHRyPEJ5dGVBcnJh
eT4gYXJyOwogCiAgICAgaWYgKENGRXF1YWwodXRpLmdldCgpLCBqcGVnVVRJKCkpKSB7CiAgICAg
ICAgIC8vIEpQRUdzIGRvbid0IGhhdmUgYW4gYWxwaGEgY2hhbm5lbCwgc28gd2UgaGF2ZSB0byBt
YW51YWxseSBjb21wb3NpdGUgb24gdG9wIG9mIGJsYWNrLgotICAgICAgICBSZWZQdHI8Qnl0ZUFy
cmF5PiBhcnIgPSBnZXRQcmVtdWx0aXBsaWVkSW1hZ2VEYXRhKEludFJlY3QoSW50UG9pbnQoMCwg
MCksIG1fc2l6ZSkpOworICAgICAgICBhcnIgPSBnZXRQcmVtdWx0aXBsaWVkSW1hZ2VEYXRhKElu
dFJlY3QoSW50UG9pbnQoMCwgMCksIG1fc2l6ZSkpOwogCiAgICAgICAgIHVuc2lnbmVkIGNoYXIg
KmRhdGEgPSBhcnItPmRhdGEoKTsKICAgICAgICAgZm9yIChpbnQgaSA9IDA7IGkgPCB3aWR0aCgp
ICogaGVpZ2h0KCk7IGkrKykK
</data>

          </attachment>
      

    </bug>

</bugzilla>